{"id":"SUSE-SU-2026:3597-1","summary":"Security update for libheif","details":"This update for libheif fixes the following issues:\n\nUpdate to version 1.23.1 (jsc#PED-16355).\n\nSecurity issues fixed:\n\n- CVE-2026-62289: integer underflow in Fraction constructor via double clap transform application (bsc#1273079).\n- CVE-2026-62291: heap out-of-bounds write in the uncompressed encoder when writing images with mismatched auxiliary\n  alpha dimensions (bsc#1273080).\n- CVE-2026-62292: out-of-bounds read in uncompressed unci tile range slicing (bsc#1273081).\n- CVE-2026-62377: reachable assertion in `HeifContext::get_track()` aborts on a valid-but-empty HEIF sequence file\n  (bsc#1273082).\n- Heap out-of-bounds write in the uncompressed encoder for RRGGBB images with interleaved bit-depth `\u003c= 8`\n  (bsc#1273083).\n\nChanges for libheif:\n\n- Version 1.23.1\n  + FFmpeg decoder plugin gains AV1, VVC, JPEG, and JPEG 2000/HTJ2K decoding.\n  + SVT-AV1 encoder: new `tune=iq` and `ms-ssim` tune parameters.\n  + C++ API: added getters/setters for the CLLI and MDCV HDR metadata boxes.\n  + Sequence decoder now scales the alpha auxiliary track to the main image size.\n  + Fixed pixi box writing for multi-channel images.\n  + Corrected the placement of the TAI `clock_type` field into the top 2 bits.\n  + Empty/unset plugin directory is no longer scanned.\n","modified":"2026-08-13T09:30:09.120531898Z","published":"2026-08-12T11:48:46Z","related":["CVE-2026-62289","CVE-2026-62291","CVE-2026-62292","CVE-2026-62377"],"upstream":["CVE-2026-62289","CVE-2026-62291","CVE-2026-62292","CVE-2026-62377"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263597-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273079"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273080"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273081"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273082"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-62289"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-62291"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-62292"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-62377"}],"affected":[{"package":{"name":"libheif","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.1-150700.3.18.1"}]}],"ecosystem_specific":{"binaries":[{"libheif-dav1d":"1.23.1-150700.3.18.1","libheif-jpeg":"1.23.1-150700.3.18.1","libheif-rav1e":"1.23.1-150700.3.18.1","libheif1":"1.23.1-150700.3.18.1","libheif-aom":"1.23.1-150700.3.18.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3597-1.json"}},{"package":{"name":"libheif","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.1-150700.3.18.1"}]}],"ecosystem_specific":{"binaries":[{"gdk-pixbuf-loader-libheif":"1.23.1-150700.3.18.1","libheif-devel":"1.23.1-150700.3.18.1","libheif-ffmpeg":"1.23.1-150700.3.18.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3597-1.json"}}],"schema_version":"1.9.0"}